Regulation

Fair Credit Reporting Act and AI use cases

US rules on consumer reports, their accuracy and permissible use, relevant to credit scoring and screening.

Read the source text (Federal Trade Commission)

High risk under the EU AI Act

Listed in Annex III or a safety component: risk management, data governance, logging, human oversight and conformity assessment are required.

  • AI credit scoring with alternative data for thin file applicants

    Annex III point 5(b): AI systems intended to evaluate the creditworthiness of natural persons or establish their credit score are high risk, except systems used to detect financial fraud. Providers need risk management, data governance, logging and human oversight. Deployers must carry out a fundamental rights impact assessment before use (Article 27), and affected persons have a right to an explanation of individual decisions from the deployer (Article 86).

Depends on design under the EU AI Act

The tier depends on how the system is used, for example whether it decides on access to an essential service.

  • AI drafted explanations for credit declines and adverse actions

    The drafting assistant does not assess creditworthiness, so on its own it is not the Annex III point 5(b) credit scoring system. It helps the lender meet the Article 86 right of affected people to a clear and meaningful explanation of decisions based on such a high risk system. If it is built into the scoring system it shares that system's high risk obligations; as a separate drafting tool its tier depends on its design and on how its output is reviewed. The follow up chat assistant must tell customers they are dealing with an AI system (Article 50).

  • AI for application and identity fraud detection

    Annex III point 5(b) excludes AI used to detect financial fraud from the high risk credit scoring category, but a system that in effect decides on creditworthiness is high risk, and remote biometric identification is high risk under point 1(a), which excludes one to one biometric verification. When a public authority uses the model on claims for public benefits, point 5(a) can apply, because it covers AI used to grant, reduce, revoke or reclaim benefits and has no fraud exception. Keep fraud detection separate from the credit or eligibility decision and use biometrics only for one to one verification.